m3rx is a newly identified ransomware group that emerged in late April 2026, recognized for its rapid operational activity and deployment of a Go-based encryptor. It utilizes a double extortion model, encrypting files and threatening to release stolen data if ransom payments are not made.
Key insights
•Employs a double extortion model with both data encryption and threat of public release of stolen data.
•Utilizes a Go-based PE32+ x64 encryptor that renames files with a .8hmlsewu extension.
•Demands payment in Bitcoin after negotiation while leveraging sensitive data exposure to press victims.
•Erases its own traces by self-deletion through PowerShell post-execution.
•Targets diverse sectors and countries, impacting organizations globally.